<?php
($goods_id = (int)_POST('goods_id')) || abort('无效参数!');

($content = _POST('content')) || abort('评论不能为空!');

$content = htmlspecialchars($content);

$star = (int)_POST('star');

$username = $_SESSION['user']['name'];
$user_id = $_SESSION['user_id'];
$data = [
  'comment_type ' => 2,
  'id_value ' => $goods_id,
  'email' => '',
  'user_name' => $username,
  'content' => $content,
  'comment_rank ' => $star,
  'add_time ' => time(),
  'ip_address ' => get_client_ip(),
  'status ' => 1,
  'parent_id' => 0,
  'user_id' => $user_id
];

if ($GLOBALS['db']->autoExecute($GLOBALS['ecs']->table('comment'), $data, 'INSERT'))
{
    return [];
}
else
{
    abort('评论失败!');
}